Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-07T20:00:00

Updated: 2024-08-07T01:35:53.730Z

Reserved: 2010-05-06T00:00:00

Link: CVE-2010-1848

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-08T00:30:01.630

Modified: 2019-12-17T20:26:08.287

Link: CVE-2010-1848

cve-icon Redhat

Severity : Important

Publid Date: 2010-05-13T00:00:00Z

Links: CVE-2010-1848 - Bugzilla